CVE-2025-48055

8.5

Combodo · iTop

Combodo iTop versions prior to 3.2.2 are vulnerable to a cross-site scripting attack when displaying content within a browse brick in the user portal.

Executive summary

A stored cross-site scripting vulnerability in Combodo iTop allows authenticated users to execute malicious scripts in the user portal, potentially leading to session hijacking or unauthorized actions.

Vulnerability

This is a cross-site scripting (CWE-79) vulnerability occurring in the user portal browse brick functionality. The flaw requires an attacker to have low-level authenticated access to the system to inject malicious scripts into the interface.

Business impact

The vulnerability carries a CVSS score of 8.5, reflecting a significant risk due to the potential for unauthorized data access and session manipulation. Successful exploitation allows an attacker to execute scripts in the context of other users, which could lead to the compromise of sensitive IT service management data or administrative account takeover, causing operational disruption and reputational harm.

Remediation

Immediate Action: Upgrade Combodo iTop to version 3.2.2 or 3.3.0 to resolve the vulnerability.

Proactive Monitoring: Review web server and application access logs for unusual patterns, such as unexpected script tags or encoded characters being submitted to the browse brick component.

Compensating Controls: Implement a strict Content Security Policy (CSP) to restrict the execution of unauthorized scripts within the browser, providing a layer of defense until the patch is deployed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS severity rating, organizations should prioritize patching their iTop instances. While the attack requires authenticated access, the potential for lateral movement or administrative compromise necessitates prompt remediation to secure the IT service management environment.

More Combodo CVEs

Sources